CVE-2026-17626: Langflow is affected by security vulnerabilities in Model Context Protocol features
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17626?
The severity of CVE-2026-17626 is high, with a CVSS score of 8.8.
How do I fix CVE-2026-17626?
To fix CVE-2026-17626, update IBM Langflow to version 1.10.4 or later.
What impact does CVE-2026-17626 have on my system?
CVE-2026-17626 can allow an authenticated attacker to read, modify, or expose sensitive host files.
Who is affected by CVE-2026-17626?
IBM Langflow OSS versions from 1.0.0 to 1.10.3 are affected by CVE-2026-17626.
What are the conditions for exploitation of CVE-2026-17626?
CVE-2026-17626 requires an attacker to be authenticated to exploit vulnerabilities in Docker-based MCP servers.